Given a foothold, identify the fastest reliable path to root or SYSTEM using the target's own features, then execute it without destabilizing the host. The critical skill is matching the misconfiguration or privilege to the correct built-in escalation technique.
Start practicing
Escalation and Exploitation — choose a session length
Free · No account required
Domain overview
This GPEN domain covers turning limited access into root or SYSTEM: kernel exploits, Windows privilege abuse, and service misconfigurations. Questions are scenario-based, asking you to pick the correct escalation path, tool, or built-in Windows feature, and to recognize why an action is risky or destructive during a sanctioned penetration test.
Exam objectives
Kernel exploit risk: crashes, instability, and potential denial of service on production hosts
SQL injection to RCE via xp_cmdshell on Microsoft SQL Server
Windows Backup Operators abusing SeBackupPrivilege and built-in utilities like robocopy or diskshadow
Linux cron jobs running writable scripts as root for privilege escalation
Running kernel exploits on production without confirming the exact kernel build and having a rollback plan, causing crashes.
Assuming Backup Operators can read files directly; the privilege must be enabled and used via a backup-aware tool.
Overlooking that xp_cmdshell is disabled by default and requires sysadmin rights or sp_configure to re-enable.
Click any question to see the full explanation and answer options, or start a focused practice session above.
You have gained standard user execution rights on a hardened Windows 10 enterprise workstation and need to enumerate local privilege escalation vectors. Which TWO methods are most effective for identifying insecure file permissions or unquoted service paths? (Choose two)
2You have identified an SUID binary on a Linux system that executes a shell command without using an absolute path. What is the most effective way to exploit this for privilege escalation?
3During a penetration test, you successfully exploit a web application via SQL injection. You want to use this access to achieve remote code execution (RCE) on the underlying Windows database server. Which feature should you look for to facilitate this?
4Which of the following is a primary goal during the 'Exploitation' phase of a penetration test?
5You are performing a penetration test and discover a service running as SYSTEM that is vulnerable to DLL hijacking. What is the most appropriate action to take to ensure the test is successful and safe?
6When escalating privileges using a Kernel exploit, why is it considered a high-risk activity for a penetration test?
7During an internal assessment, you gain a foothold as a low-privileged domain user on a Windows Server 2019 host that is a member of an Active Directory domain. You run whoami /priv and observe SeImpersonatePrivilege enabled in your token. You need to escalate to NT AUTHORITY\SYSTEM on this host. Which technique is most appropriate?
8You have obtained a Meterpreter session as a standard user on an Ubuntu 20.04 server during an authorized penetration test. You want to identify reliable local privilege escalation vectors. Which two findings most directly indicate a path to root? (Choose two.)
9During an internal assessment you obtain a Meterpreter session on a Windows Server 2016 host running as a low-privileged service account. You want to identify whether the host is missing security updates that could allow local privilege escalation without immediately running an exploit. Which Metasploit post-exploitation module should you use to enumerate installed hotfixes and compare them against known vulnerabilities?
10While testing a Windows 10 workstation, you find that the account you compromised belongs to the Backup Operators group. You need to escalate to local administrator without installing third-party tools on disk. Which built-in capability of this group can you abuse to obtain administrative access?
11You have obtained a Meterpreter session on a Windows 10 host as a standard user. You want to escalate privileges by exploiting a vulnerable kernel driver. Which Metasploit module category would you use to search for suitable exploits?
12You have a shell as www-data on an Ubuntu 20.04 web server and notice a cron job that runs every minute as root executing a script located in /opt/backup/run.sh. The script is writable by the www-data user. What is the most direct way to escalate privileges in this situation?
13During a penetration test on a Linux server, you find a cron job that runs every minute as root: '*/1 * * * * root /usr/local/bin/backup.sh'. The script is owned by root but has permissions 777. You are a low-privileged user. What is the most direct way to escalate privileges?
14You are performing a penetration test on a Linux system and have obtained a low-privileged shell. You want to escalate privileges by exploiting misconfigured file permissions. Which two of the following file permission scenarios are most likely to allow privilege escalation? (Choose two.)
15During a Linux assessment you find a root-owned binary with the SUID bit set that calls the system() function using a relative path, such as system("cat /etc/hostname"). The binary's directory is not writable, but your current directory is. Which technique is most likely to let you execute arbitrary code as root?
16You compromise a Windows workstation and extract the NTLM hash of a local administrator account that is reused across many workstations in the domain. You want to authenticate to remote hosts without cracking the hash. Which technique should you use?
17During a Windows assessment you obtain a low-privileged domain user's credentials. Enumeration reveals a Group Policy Preference file on a readable SYSVOL share containing a cpassword value. What is the most effective next step to escalate privileges?
Given a foothold, identify the fastest reliable path to root or SYSTEM using the target's own features, then execute it without destabilizing the host. The critical skill is matching the misconfiguration or privilege to the correct built-in escalation technique.
The Courseiva GPEN question bank contains 17 questions in the Escalation and Exploitation domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Escalation and Exploitation domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included